Stage the install
Use a spare project or worktree the first time. Never debut an unknown plugin on the monorepo that pays your rent.
Capture your Claude Code config before and after (a quick git commit of dotfiles helps). Rollbacks should be boring.
Evaluate with a fixed script
Write three tasks you already know the answer to. Run the plugin’s recommended commands. Score accuracy, speed, and whether it asked for surprising permissions mid-flight.
If the plugin wants MCP servers, enable one at a time. Bundling five new MCP endpoints in a single afternoon guarantees you will not know which one leaked data.
Team rollout
Document the approved plugin list in-repo. Shadow IT Claude plugins are how secrets wander into third-party tools.
Revisit the list quarterly — or after any incident. Pair with the rating scorecard so removals are evidence-based, not political.